CVE-2022-39168: High severity ibm robotic process automation for services vulnerability
Published Sep 26, 2022
·Updated
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs.
Affected Software
9 affected components
IBM Robotic Process Automation=21.0.3
IBM Robotic Process Automation=21.0.4
IBM Robotic Process Automation for Cloud Pak=21.0.3
IBM Robotic Process Automation for Cloud Pak=21.0.4
IBM Robotic Process Automation For Services=21.0.3
IBM Robotic Process Automation For Services=21.0.4
IBM Robotic Process Automation for Cloud Pak<=21.0.3, 21.0.4
IBM Robotic Process Automation as a Service<=21.0.3, 21.0.4
IBM Robotic Process Automation<=21.0.3, 21.0.4
Remediation
Patch Available
Event History
Sep 26, 2022
CVE Published
via IBM·12:00 AM
Sep 29, 2022
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-39168.
2
What is the severity of CVE-2022-39168?
The severity of CVE-2022-39168 is high (7.5).
3
Which IBM products are affected by CVE-2022-39168?
IBM Robotic Process Automation for Cloud Pak, IBM Robotic Process Automation as a Service, and IBM Robotic Process Automation are affected by CVE-2022-39168.
4
What is the risk of CVE-2022-39168?
CVE-2022-39168 poses the risk of proxy credentials being exposed in upgrade logs.
5
How can I find more information about CVE-2022-39168?
You can find more information about CVE-2022-39168 on the IBM X-Force website and the IBM Support page.